currently, we running following products, How can we fix those two Vulnerabilities?
We are currently running:
Bamboo - 8.0.4
Bitbucket - 7.17.5
Confluence - 7.13.7
Crowd - 4.4.0
Jira - 8.20.10
Jira Service Management - 4.20.10
I am new for those products, could you give me the steps to fix, Thanks
Everything about both CVE's you can find here - https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html
You need to upgrade your apps to versions mentioned in above document. How to upgrade? Every app has docs about that. Search on confluence.atlassian.com.
Regards,
Seba
Is there any chance for identifying a workaround that would only patch applications in their existing version instead of having to upgrade?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi
If there is nothing about workaround I'm afraid that upgrade is the only way to fix it.
You can also talk with network/security engineers to block access to your instances from the Internet or you can talk with them about some solution that will prevent you any security issues (e.g. WAF for Azure or something similar).
Regards,
Seba
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Your Confluence instance is not vulnerable, but I am in the same boat as you with the other systems. As there are no workarounds, I am planning to upgrade them ASAP and I would suggest you do the same.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.